Date-stamp loading
Version date: 8 December 2023 - onwards
    Version 1 of 1    

4.2.2 Content of major incident notifications and reports, and notifications of significant cyber threats (paras. 21-26)

Closed
4 March 2024

21. When developing the draft RTS, the ESAs have considered various data fields to be included in the reporting requirements ensuring a balanced approach in the reporting of incidents, where:

- CAs receive all essential information about the major incident that will be of their interest;

- FEs do not face unnecessary reporting burden; and

- The information collected is useful for NIS2 authorities and resolution authorities due to the lex specialis nature of DORA to other legislations, namely NIS2.

22. The ESAs have proposed that the incident reporting template cover 37 specific types of data, spread between general information about the reporting FE (7 types of data), initial notification (7 types of data), intermediate report (16 types of data) and final report (7 types of data). The incident reporting template includes the following data types split by notification/reports:

a) General information - Type of report; Name, type and LEI code of the reporting and/or affected financial ent

Comparing proposed amendment...